软件产品网络中的漏洞扩散

Vulnerability diffusions in software product networks

JOURNAL OF OPERATIONS MANAGEMENT · 2023
被引 6
人大 AFT50UTD24ABS 4*

中文导读

研究了软件产品网络中漏洞如何通过节点间的连接扩散,基于12年国家漏洞数据库数据,用网络理论和机器学习分析边缘动态、开发者响应等因素的影响。

Abstract

Abstract During software product development, the combination of digital resources (such as application programming interfaces and software development kits) establishes loose and tight edges between nodes, which form a software product network (SPN). These edges serve as observable conduits that may help practitioners and researchers better understand how vulnerabilities diffuse through SPNs. We apply network theory to analyze data from over 12 years of records extracted from the National Vulnerability Database. We contribute novel measures established using machine learning to gauge the properties influencing vulnerability diffusion within an SPN. We observed an SPN having a discernable shape that changed over time via network updates. We propose hypotheses and find empirical evidence that vulnerability diffusion is influenced by edge dynamics, developer responses, and their interaction. Implications for practice are that increased developer responses reduce software vulnerability diffusion attributed to edge dynamics.

软件工程网络安全网络科学数据挖掘